A county discovers constrained Kerberos delegation configured on several service accounts. How should the assessment treat that finding?
Select an answer to reveal the explanation.
Short Explanation
"Constrained" sounds like a seatbelt, but the belt only helps if it is clipped to the right posts. Allowed services and targets still decide how far impersonation can travel. Review the map — do not trust the label alone.
Full Explanation
Constrained delegation restricts which services an account may impersonate users toward, yet mis-scoped targets or sensitive SPNs can still create high-impact abuse paths. Naming does not equal safety; configuration review is required. Skipping constrained objects because unconstrained ones exist leaves residual risk unreported. Delegation presence also does not by itself prove Domain Admin compromise.